Fake Minecraft Clients Push WeedHack Malware

Infosecurity Magazine · Medium sophistication
Last updated August 25, 2026

Attackers are tricking Minecraft players into downloading malware by impersonating popular Minecraft clients and resellers in Google search results. Even after the campaign’s command-and-control infrastructure was taken down, the operation continued by shifting distribution to common file-hosting platforms like Discord, MediaFire, GitHub, and Dropbox.

Key findings

  • McAfee observed ongoing activity from the WeedHack campaign after an earlier takedown of its command-and-control infrastructure.
  • Attackers used SEO poisoning and fake websites impersonating legitimate Minecraft clients to put malicious downloads in front of gamers.
  • The campaign shifted to distributing malware via mainstream file-hosting services, especially Discord, plus MediaFire, GitHub, and Dropbox.
  • Some fake sites lured users with offers like free versions of paid tools or cracked software.

Who’s being targeted

  • Commonly targeted roles: Gamers/Players, Students, Helpdesk/IT support (endpoint protection guidance), Parents/Guardians (home device safety).
  • Affected industries: Gaming, Consumer/End users, Education (students/gamers).
  • Attack channels: website, discord.
  • Impersonated: Legitimate Minecraft client/reseller site (e.g., a popular client such as “Xenon Client”), A Minecraft mod/client uploader using Discord file hosting.

Awareness takeaways

  • Only download mods/clients/tools from trusted, official sources (not “top Google results” or lookalike sites).
  • Be skeptical of “free” offers for paid tools/cracked software, these are common bait for malware.
  • Keep security software enabled and scan downloads before opening them.
  • Check links carefully for lookalike domains before downloading anything.

Red flags to watch for

  • Arrives via a lookalike website that imitates a known Minecraft client/reseller
  • Promotes “free versions of paid tools” or “cracked software” as a lure
  • Download is pushed via search results influenced by SEO manipulation
  • Uses a general-purpose file-hosting link instead of an official project site
  • Unexpected executable download for a “client/mod”
  • Link origin does not match the official source for the tool
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You Google a Minecraft client like “Xenon Client” and click the top result, without thinking. That’s the WeedHack trap. WeedHack uses SEO poisoning and lookalike Minecraft client sites that promise free or cracked tools. You click download…and the file actually comes from Discord, MediaFire, GitHub, or Dropbox, not the real project site. Here’s the tell: a “free” version of a paid Minecraft tool, hosted on a generic link like Discord or MediaFire, and the URL doesn’t match the official client site. If the download is an unexpected EXE for a mod, that’s your red flag. One move: only download Minecraft clients and mods from the official project site you type in yourself, then let your security software scan the file before you run it.

Similar attacks

Fake Minecraft Client Sites Still Push WeedHack

Fake Minecraft Client Sites Still Push WeedHack

Researchers report that the WeedHack malware campaign is still infecting people through convincing fake Minecraft client/mod websites, even after its command-and-control server was disrupted. Attackers use SEO poisoning and trusted community platforms (like Discord and Minecraft modding sites) to…

August 25, 2026
Fake Claude & Perplexity Lures Push Malware

Fake Claude & Perplexity Lures Push Malware

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings…

August 21, 2026
DEF CON Attendees Hit With Fake CoinDesk DMs

DEF CON Attendees Hit With Fake CoinDesk DMs

After Black Hat/DEF CON, cybercriminals allegedly targeted conference attendees by impersonating a CoinDesk executive over X direct messages. Victims were pushed into a realistic workflow using Google Docs and a fake Dropbox DocSend installer to trick them into running malware on macOS or Windows.

August 21, 2026
Spoofed Portal Drops APT36 Backdoor on Telecoms

Spoofed Portal Drops APT36 Backdoor on Telecoms

The bulletin describes an APT36 (Transparent Tribe) espionage campaign that uses social-engineering lures and spoofed download portals to trick targets into installing a malicious Windows installer. The installer (“TMS_AfghanTelecom.exe”) deploys the PATCHCORD backdoor, which then calls out to…

August 18, 2026
Fake GitHub Repos and Trojan Apps Steal Data

Fake GitHub Repos and Trojan Apps Steal Data

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to trick people into installing credential and crypto-stealing malware, and another uses hundreds of imposter GitHub repositories to lure…

July 17, 2026
Fake GTA 6 Demo Sites Push Password Stealer

Fake GTA 6 Demo Sites Push Password Stealer

Attackers are exploiting GTA 6 hype by creating convincing fake Rockstar-branded “demo” websites that appear in Google search results. The sites use “Play Now”/“Official Download” lures to trick people into downloading a small Windows executable that installs Vidar infostealer and steals saved…

August 24, 2026